RANSOMWARE VICTIMEDUCATIONDUPLICATE CLAIM

North Stonington Elementary School

northstonington.k12.ct.us
interlock📍 United States (US)📅 October 13, 2025
1
linked CVEs
8
same group

Attack Intelligence

North Stonington Elementary School was compromised in a ransomware attack attributed to interlock in October 2025. The organization, operating in the Education sector in United States, was added to the group's data leak site as part of an extortion campaign.

interlock operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

https://www.northstonington.k12.ct.us North Stonington Public Schools have two public schools and 736 students, strives to create a safe environment for themselves, their school, and their students. However, their "Safety First" slogan has recently changed! Despite having extensive resources and support, North Stonington Public Schools has a very poor IT security team that is doing a poor job! With our help, over 3 TB of confidential data was exposed, meaning all student data, including the entire history and documentation, is now in our hands!

Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-20131, which may have been leveraged as initial access vectors or for lateral movement.

Additional Details

Correlated Vulnerabilities (1)

Other Victims — interlock (8)

Quick Facts

CountryUnited States (US)
SectorEducation
Attack DateOct 13, 2025
Domainnorthstonington.k12.ct.us
Intel Sourceransomlook
StatusDUPLICATE CLAIM

Threat Group

interlock
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.